← العودة للجدول
CVE-2026-53673
CVE-2026-53673 — BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in
📅 2026-06-10
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 8.1

📋 الوصف الكامل

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a user_id parameter in the request. Attackers can pass another user's identifier to the get_item_permissions_check method, which validates the supplied user_id instead of the logged-in user and is reu

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-53673

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-53673 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←